A memory leak in archive_read_format_zip_cleanup in archive_read_support_format_zip.c in libarchive through 3.3.3 allows remote attackers to cause a denial of service via a crafted ZIP file because of a HAVE_LZMA_H typo. Reference: https://github.com/libarchive/libarchive/issues/1165 Upstream commit: https://github.com/libarchive/libarchive/commit/ba641f73f3d758d9032b3f0e5597a9c6e593a505
Created libarchive tracking bugs for this issue: Affects: fedora-all [bug 1702209] Created mingw-libarchive tracking bugs for this issue: Affects: fedora-all [bug 1702210]
Created libarchive tracking bugs for this issue: Affects: epel-6 [bug 1702211]
Introduced via https://github.com/libarchive/libarchive/commit/121035c83e18b70d3128e9ac966109ebedb7e516 and later changed a bit in https://github.com/libarchive/libarchive/commit/786e734872d80a7676a486a6f1d45ee29710628f
Statement: This issue did not affect the versions of libarchive as shipped with Red Hat Enterprise Linux 6 and 7.